These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-9123 is a heap buffer overflow in Chromecast functionality in Google Chrome on Android, Linux, and ChromeOS. According to the CVE description, versions prior to 148.0.7778.179 could let a local attacker use malicious network traffic to execute arbitrary code inside a sandbox. The NVD record classifies the issue as high severity (CVSS 7.5), while the Chromium severity label in the source metadata [truncated]
CVE-2026-9122 is a medium-severity information-disclosure issue in Google Chrome on Mac fixed in version 148.0.7778.179. According to the official NVD entry and Google/Chromium references, a remote attacker could use a crafted HTML page to trigger an out-of-bounds read in the GPU component and potentially obtain sensitive data from process memory. The issue is published on 2026-05-20, has CVSS 3.1 score 6 [truncated]
CVE-2026-9121 describes an out-of-bounds read in Chrome's GPU component that could be triggered remotely through a crafted HTML page. The issue affects Chrome versions prior to 148.0.7778.179 and is described as potentially leading to heap corruption. NVD assigns a CVSS 3.1 base score of 8.8 (HIGH), while Chromium’s own severity label is Medium, so defenders should treat it as an important browser update [truncated]
CVE-2026-9120 is a high-severity use-after-free in WebRTC within Google Chrome before 148.0.7778.179. According to the CVE record, a remote attacker could execute arbitrary code by getting a victim to open a crafted HTML page. The published CVSS vector reflects network-based exploitation with user interaction required, and the impact is rated high for confidentiality, integrity, and availability.
CVE-2026-9119 is a high-severity memory corruption issue in WebRTC as used by Google Chrome. A remote attacker could potentially trigger arbitrary code execution inside the browser sandbox by getting a user to open a crafted HTML page. The NVD record ties the issue to Chrome versions prior to 148.0.7778.179 and lists CWE-122 (heap-based buffer overflow).
CVE-2026-9118 is a high-severity use-after-free flaw in Chrome’s XR handling on Windows that could let a remote attacker execute arbitrary code if a user opens a crafted HTML page. The issue is tracked as CWE-416 and carries a CVSS 3.1 score of 8.8, reflecting network attackability with user interaction required.
CVE-2026-9117 is a High-severity Chrome issue involving type confusion in GFX on Linux and ChromeOS. The CVE description says a remote attacker who had already compromised the renderer process could potentially achieve a sandbox escape by using a crafted video file. Affected builds are Chrome prior to 148.0.7778.179.
CVE-2026-9116 affects Google Chrome prior to 148.0.7778.179. According to the CVE description, insufficient policy enforcement in ServiceWorker could allow a remote attacker to leak cross-origin data from a crafted HTML page. NVD lists the issue as CVSS 4.3 (Medium), while Chromium labels it High severity, so it is worth prioritizing browser updates even though user interaction is required.
CVE-2026-9115 describes an insufficient policy enforcement issue in Google Chrome’s Service Worker handling that could let a remote attacker bypass same-origin policy by getting a user to load a crafted HTML page. The issue is reported as affecting Chrome versions prior to 148.0.7778.179. Although the NVD CVSS score is 4.3 (Medium), Chromium’s own severity label is High, so browser operators should treat [truncated]
CVE-2026-9114 is a high-severity use-after-free in Google Chrome’s QUIC handling. According to the published description, a remote attacker could trigger the flaw with malicious network traffic and potentially achieve arbitrary code execution inside the browser sandbox on affected versions prior to 148.0.7778.179.
CVE-2026-9113 is an out-of-bounds read in the GPU component of Google Chrome on macOS. According to the CVE description, a remote attacker could trigger the issue through a crafted HTML page in Chrome versions prior to 148.0.7778.179. The NVD record maps the issue to CWE-125 and shows a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N, indicating user interaction is required and the primary impact i [truncated]
CVE-2026-9112 is a high-severity use-after-free in Chrome’s GPU component on Windows. According to the CVE description, a remote attacker could trigger the flaw with a crafted HTML page and execute arbitrary code inside the browser sandbox on versions prior to 148.0.7778.179. NVD lists CWE-416 and a CVSS 3.1 score of 8.8, reflecting the potential impact of a successful browser compromise.
CVE-2026-9111 is a browser memory-safety flaw in Chrome’s WebRTC component on Linux. A crafted HTML page could trigger a use-after-free condition and allow remote code execution before version 148.0.7778.179. The supplied Chromium advisory labels the issue Critical, while NVD currently lists a CVSS 3.1 score of 8.8 (HIGH).
CVE-2026-9110 is a Chrome-on-Windows UI spoofing issue fixed in Google Chrome 148.0.7778.179 and earlier affected builds. The public description says the flaw could be abused only after a remote attacker had already compromised the renderer process, allowing a crafted HTML page to spoof UI. That makes this a post-compromise deception issue rather than a standalone initial access bug. Chromium labeled the [truncated]
CVE-2026-8587 is a Chrome Extensions use-after-free issue affecting Google Chrome on Mac before version 148.0.7778.168. A user must be persuaded to install a malicious extension, after which a crafted extension can lead to arbitrary code execution. The CVSS 3.1 score is 8.8 (High), while Chromium’s severity label is Medium.
CVE-2026-8586 is a medium-severity local access control bypass in Google Chrome's Chromoting component, affecting versions prior to 148.0.7778.168. The vulnerability stems from an inappropriate implementation that allows a local attacker to bypass discretionary access control by leveraging a malicious file. The CVSS 3.1 vector (AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L) indicates an attack vector adjacent to th [truncated]
## Summary CVE-2026-8585 is an inappropriate implementation vulnerability in the Media component of Google Chrome on iOS. A remote attacker who has already compromised the renderer process can trigger an out-of-bounds memory read by convincing a user to visit a crafted HTML page. Google rates this flaw as Medium severity; NVD assigns a CVSS 3.1 score of 7.5 (High). ## Affected Products - Google Chrome on [truncated]
A UI spoofing vulnerability in Google Chrome on iOS, rated Medium severity (CVSS 4.2), was addressed in version 148.0.7778.168. The flaw stemmed from inappropriate implementation in Views, allowing a remote attacker who had already compromised the renderer process to spoof UI elements via a crafted HTML page. The attack requires high complexity and user interaction, with limited confidentiality and availa [truncated]
CVE-2026-8583 is a medium-severity information disclosure vulnerability in Google Chrome on Android, affecting versions prior to 148.0.7778.168. The flaw stems from insufficient policy enforcement in the WebXR API, which could allow a remote attacker who has already compromised the renderer process to extract potentially sensitive information from process memory via a crafted HTML page. The vulnerability [truncated]
A medium-severity information disclosure vulnerability in Google Chrome's Dawn graphics component allows remote attackers to extract potentially sensitive data from process memory via a crafted HTML page. The flaw stems from an object lifecycle management issue in Dawn, Chrome's WebGPU implementation. Affected versions include all Chrome releases prior to 148.0.7778.168. Google addressed this vulnerabilit [truncated]
A use-after-free vulnerability in Mojo, Chrome's inter-process communication framework, enables remote sandbox escape via crafted HTML. The flaw affects Google Chrome versions prior to 148.0.7778.168. Google assigned Medium severity internally; NVD analysis yields CVSS 9.6 (Critical) based on network attack vector, low complexity, no privileges required, user interaction, scope change, and high impacts ac [truncated]
CVE-2026-8579 is a medium-severity vulnerability in Google Chrome's Skia graphics library, published on May 14, 2026, and last modified on May 19, 2026. The flaw stems from insufficient validation of untrusted input when processing crafted print files, enabling a remote attacker who has already compromised the renderer process to perform an out-of-bounds memory write. The CVSS 3.1 score of 3.1 (Low) refle [truncated]
CVE-2026-8578 describes an out-of-bounds read in Chrome's GPU path on Linux that could leak cross-origin data from a crafted HTML page after the renderer process has already been compromised. Google and NVD published the record on 2026-05-14, and NVD updated it on 2026-05-21. The issue is fixed in Chrome 148.0.7778.168 and later.
CVE-2026-8576 describes a Chrome CORS implementation issue that could let a remote attacker leak cross-origin data from a crafted HTML page. NVD rates it Medium (CVSS 4.3), and the fix is identified as Chrome 148.0.7778.168 or later.
Use-after-free vulnerability in Google Chrome's UI component, enabling sandbox escape from compromised renderer process.
A use-after-free vulnerability in Google Chrome's Core component on Windows allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability requires user interaction and high attack complexity, but successful exploitation could lead to complete system compromise. Google has rated this as Medium severity per Chromium's internal scale, t [truncated]
Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
A policy enforcement gap in Chrome's Network component on Android allowed a compromised renderer process to leak cross-origin data. The vulnerability was addressed in Chrome 148.0.7778.168.
A sandbox escape vulnerability in Google Chrome on Android, stemming from insufficient policy enforcement in the GPU component. A remote attacker who has already compromised the renderer process could leverage this flaw to escape the browser sandbox via a crafted HTML page. The vulnerability affects Chrome versions prior to 148.0.7778.168 on Android. Google has assigned this a Medium severity rating, whil [truncated]
A type confusion vulnerability in Google Chrome's V8 JavaScript engine, fixed in version 148.0.7778.168, could allow remote attackers to extract sensitive information from process memory via a crafted HTML page. The vulnerability was published on May 14, 2026, and last modified on May 19, 2026. Google has rated this as Medium severity. The issue stems from improper type handling in V8 (CWE-843), which can [truncated]